Weaknesses of type CWE-125

5,159 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2026-38971CRITICALardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINEPSS 0.7%CVE-2026-43112HIGHfs/smb/client: fix out-of-bounds read in cifs_sanitize_prepathEPSS 0.7%CVE-2021-38451MEDIUMAUVESY VersiondogEPSS 0.7%CVE-2022-3447MEDIUMInappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the conteEPSS 0.7%CVE-2022-41977MEDIUMAn out of bounds read vulnerability exists in the way OpenImageIO version v2.3.19.0 processes string fields in TIFF image files. A speciallyEPSS 0.7%CVE-2026-35423MEDIUMWindows 11 Telnet Client Information Disclosure VulnerabilityEPSS 0.7%CVE-2024-29994HIGHMicrosoft Windows SCSI Class System File Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2022-39317MEDIUMOut of bounds read in zgfx decoder in FreeRDPEPSS 0.7%CVE-2023-3646MEDIUMOn affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.EPSS 0.7%CVE-2023-39176MEDIUMKernel: ksmbd: transform header out-of-bounds read information disclosure vulnerabilityEPSS 0.7%CVE-2026-34824HIGHMesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of ServiceEPSS 0.7%CVE-2026-85455HIGHMOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short PacketEPSS 0.7%CVE-2025-15646CRITICALHTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusionEPSS 0.7%CVE-2026-76151MEDIUMOut-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)EPSS 0.7%CVE-2022-28228CRITICALOut-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensEPSS 0.7%CVE-2026-41475HIGHBACnet Stack: Out-of-Bounds Read in WritePropertyMultiple Decoder via Deprecated Tag ParserEPSS 0.7%CVE-2025-49689HIGHMicrosoft Virtual Hard Disk Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2025-24987MEDIUMWindows USB Video Class System Driver Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2024-3859MEDIUMOn 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenTypEPSS 0.7%CVE-2025-24988MEDIUMWindows USB Video Class System Driver Elevation of Privilege VulnerabilityEPSS 0.7%